Client Success Story - Implementing ServiceNow GRC for compliance at Engineering & Construction Firm
Project Overview
ImagineX Approach
- As a security audit practice, the Information Security organization performs annual security audits for their primary locations following the ISO-27001 standards that includes all legal, physical and technical controls involved in their information risk management processes. The existing ServiceNow customer elected to implement GRC to meet their program objectives.
- Over the course of a four-month initiative we implemented the following capabilities for the client:
- Implemented Policy Compliance & Audit Management modules
- Custom issue management extension
- Updated audit reporting and SLA workflows
- Published IT Security Standards to the GRC knowledgebase
- Defined and loaded 200+ policy statements with elements from both ISO27001 & ISO27002
- Generated over 3000+ controls based on the policy statements and defined profiles
- Extended the Audit Engagement module to manage follow-on activities documented as issues during audit
- Implemented a custom 5×5 risk scoring system based on issue type, category, rating & probability
- Implemented SLAs and notification reminders for upcoming audit follow-on activities coming due
Project Success
Technology & Tools
Governance, Risk & Compliance, Policy & Compliance, Audit Management, ServiceNow GRC, ServiceNow Policy Compliance & Audit Management
Methodology
Agile, ISO27001, ISO27002